CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,712 vulnerabilities with CWE-94
CVE-2026-46442 CRITICAL
Flowise: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox Escape
CVSS 9.9
CVE-2026-11520 LOW
SourceCodester Inventory System header.php cross site scripting
CVSS 3.5
CVE-2026-11518 MEDIUM
SourceCodester Inventory System User Management users.php cross site scripting
CVSS 4.3
CVE-2026-11512 MEDIUM
itsourcecode Hospital Management System billing.php cross site scripting
CVSS 4.3
CVE-2026-11491 LOW
CodeAstro Human Resource Management System Notice Board Management All_notice cross site scripting
CVSS 2.4
CVE-2026-11468 LOW
SourceCodester Hospitals Patient Records Management System page room_types cross site scripting
CVSS 2.4
CVE-2026-11436 MEDIUM
Mage AI Sign-in Flow index.tsx useMutation cross site scripting
CVSS 4.3
CVE-2026-11434 LOW
FluentCMS Blocks Plugin blocks cross site scripting
CVSS 2.4
CVE-2026-49493 HIGH
Markdown Preview Enhanced Arbitrary Code Execution via Bitfield interpretJS()
CVSS 8.8
CVE-2026-11338 LOW
SourceCodester Ship Ferry Ticket Reservation System manage_user cross site scripting
CVSS 2.4
CVE-2026-11337 MEDIUM
tittuvarghese CollegeManagementSystem fetch.php cross site scripting
CVSS 4.3
CVE-2026-11231 HIGH
Google Chrome - Arbitrary Code Execution
CVSS 8.1
CVE-2026-11218 MEDIUM
Google Chrome - Arbitrary Code Execution
CVSS 6.8
CVE-2026-11157 MEDIUM
Google Chrome - Improper Control of Generation of Code ('Code Injection')
CVSS 5.4
CVE-2026-10928 HIGH
Google Chrome - Improper Control of Generation of Code ('Code Injection')
CVSS 8.8
CVE-2026-10904 HIGH
Google Chrome - Arbitrary Code Execution
CVSS 8.8
CVE-2026-41249 HIGH
CoreShop Vulnerable to Remote Code Execution (RCE) via Insecure `pull_request_target` Configuration
CVSS 8.2
CVE-2026-10810 MEDIUM
itsourcecode Fees Management System navbar.php cross site scripting
CVSS 4.3
CVE-2026-10688 MEDIUM
ahujasid blender-mcp server.py execute_blender_code code injection
CVSS 5.5
CVE-2026-49143 HIGH
BrowserStack Runner 0.9.5 Unauthenticated RCE via /_log HTTP Handler
CVSS 8.8
CVE-2026-1829 HIGH
Content Visibility for Divi Builder <= 4.02 - Authenticated (Contributor+) Remote Code Execution
CVSS 8.8
CVE-2026-47117 CRITICAL
OpenMed < 1.5.2 Remote Code Execution via PII Model Loading
CVSS 9.8
CVE-2026-10567 LOW
1Panel-dev CordysCRM ModuleFormController ModuleFormService.java save cross site scripting
CVSS 3.5
CVE-2026-10529 LOW
westboy CicadasCMS Task Scheduling Management ScheduleJobController.java cross site scripting
CVSS 2.4
CVE-2026-10514 LOW
1Panel-dev CordysCRM RequestParamTrimConfig.java cross site scripting
CVSS 2.4
Details
Vulnerabilities 6,712
Exploit Likelihood Medium